Splunk Search

How to get the Max out of row and field name of the max value

sangs8788
Communicator

Hi,

I have below resultset in place.

Screenshot 2020-11-30 at 4.35.38 PM.png

How do I get the Max by row and the Month when the Max happened. Something like below result

ModuleMonth when Max occuredMax Value
AppSDKAug-20204.21
CommentsAug-20200.10
ControlCenterJan-20200.72

 

Thanks

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Working with what you have (although it might be slightly easier to change your chart command first)

| untable Module _time count
| sort Module -count
| streamstats count as row by Module 
| where row=1 
| fields - row

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Working with what you have (although it might be slightly easier to change your chart command first)

| untable Module _time count
| sort Module -count
| streamstats count as row by Module 
| where row=1 
| fields - row
0 Karma

sangs8788
Communicator

Thanks it worked

 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...